About Summit

Summit is a remote penetration-testing and security compliance practice. Its website is sumrite.com, which is why the company is sometimes referred to as Sumrite. Summit tests web applications, APIs, mobile apps, cloud accounts, networks, source code and desktop software by hand, and issues a VAPT report that teams use for SOC 2, ISO 27001, PCI DSS and enterprise vendor reviews. It also supports risk assessments and data protection compliance work, including PDPL programmes in the Gulf.

What Summit does

Every engagement is a manual test carried out by a security researcher, not a scanner export. Findings are reproduced before they are reported, rated by CVSS severity, and written up with evidence, steps to reproduce and a fix. For a scoped web application or API, the report is delivered within 48 hours of testing starting. Re-testing of fixed findings is included on standard engagements. See all services and a sample report.

How an engagement starts

A quote usually comes back within about 15 minutes of a request. An NDA is signed before any technical detail is exchanged, and targets, test windows and safety contacts are agreed in writing before testing begins. A quote request is never treated as permission to test.

Who Summit works with

Most clients are SaaS companies, fintech and healthtech teams and B2B software businesses, often at the point where an enterprise customer, an auditor or a regulator first asks for independent security evidence.

Where Summit works

Summit's office is at E-211 FFC, III, Okhla Industrial Estate, New Delhi, Delhi 110020, India. The testing team works remotely with clients worldwide, and Summit does not operate offices in other countries. The regional pages explain how a report maps to local regimes in the UAE, Saudi Arabia, Australia, Germany and France, and state plainly which local credentials Summit does not hold: it is not PASSI-qualified in France, not an IRAP assessor in Australia, not an NCA-licensed audit firm in Saudi Arabia and not a BSI auditor in Germany. Where a contract requires one of those, Summit declines the work.

Methodology

Testing follows recognised public methodologies: the OWASP Web Security Testing Guide, the OWASP API Security Top 10, the OWASP Mobile Application Security Verification Standard (MASVS), NIST SP 800-115, PTES and CIS Benchmarks. Red team findings are mapped to MITRE ATT&CK.

Authors

Faisal Khan, Director at Summit, oversees penetration testing, risk assessment and compliance engagements and writes for the research blog.

Niyaz Khan and Nishant Sharma, Senior Consultants at Summit, write the security hardening and compliance guides on the research blog. Articles cover security hardening, compliance testing and anonymised case studies drawn from testing work. How articles are written, checked, dated and corrected is set out in the editorial policy.

Contact

Email sales@sumrite.com, use the contact form, or follow Summit on LinkedIn. To report a vulnerability in this website, see the security disclosure policy.

Contact Summit